BissAI · Privacy Policy
Privacy Policy
Effective date: September 5, 2026 · Applies to https://bissai.netlify.app and the BissAI web app, Instagram integration, and Messenger integration.
BissAI turns social customer conversations into focused transactional workflows (booking, quotes, orders, support). A business connects Instagram or Messenger, and BissAI receives inbound messages, generates a secure one-time customer link, and runs the customer's workflow in an app-scoped session. This policy explains what we collect through Meta products, why we need it, and how to delete it. Use this same page as our Data Deletion Instructions URL for Meta App Review.
1. Overview and who we are
BissAI ("we", "us") provides a business workspace where owners create customer-facing apps, connect social channels, and serve customers through short-lived, single-use links. This policy covers visitors to our site, business account holders, and end customers who message a connected business or open a customer link.
If you are an end customer, your primary relationship is with the business you messaged. That business configures what its BissAI app collects (for example intake answers, booking details, or order information). We process that content only as a service provider to the business, inside that app's isolated data store.
2. Data we collect
A. Business owner account data
- Name and email address you provide at signup.
- Password stored only as a salted scrypt hash — never in plain text.
- Session cookie (signed, HttpOnly, SameSite) used to keep you logged in.
- Apps you create, builder prompts, preview/test activity, and workspace settings.
- Password-reset tokens (single-use, expiring; never exposed in production responses).
B. Connected Instagram business account data
- Instagram user ID, username, and account name returned by Instagram Business Login.
- OAuth access token, stored server-side only and never exposed to the browser.
- Inbound message content, sender Instagram-scoped ID, recipient business ID, message ID, and timestamp from Instagram webhooks.
- Outbound reply records (status, message text, link URL issued) for delivery auditing.
C. Connected Messenger Page data
- Facebook Page ID, Page name, and Page access token from Facebook Login, stored server-side only.
- Inbound message content, sender PSID, recipient Page ID, message ID, and timestamp from Messenger webhooks.
- Outbound reply records for delivery auditing.
D. End-customer runtime data
- Instagram-scoped ID or Messenger PSID used as the customer identity inside one app.
- One-time link tokens stored only as hashes; raw secrets never leave the server.
- Workflow inputs the customer submits (for example booking, quote, order, or support details) and interaction history, kept inside that app's dedicated store.
E. Technical data
- IP address and rate-limit counters for abuse prevention on auth and webhook endpoints.
- Webhook signature verification artifacts, error logs, and standard server logs.
- OAuth state and return-to cookies (short-lived, HttpOnly) used only during login.
We do not request or store Instagram/Facebook passwords, and we do not pull media libraries, follower lists, or ad data. Non-text events (reactions, read receipts, echoes, message edits) are ignored and not stored as customer content.
3. Meta permissions we request and why
When a business connects a channel, Meta shows exactly which permissions BissAI requests. We request the minimum needed to deliver the product:
- instagram_business_basic — identify the connected Instagram business account (user ID, username, name) so inbound messages route to the correct app.
- instagram_business_manage_messages — receive Instagram DMs via webhook, subscribe the account to the
messagesfield, and send a reply containing the customer's one-time app link. - pages_show_list — list Facebook Pages the business user administers so they can pick which Page to connect.
- pages_messaging — receive Messenger messages via webhook, subscribe the Page to
messagesandmessaging_postbacks, and send the reply containing the one-time app link.
Webhook endpoints verify every request: hub.verify_token on subscription checks and X-Hub-Signature-256 (HMAC-SHA256 with the app secret) on every POST before any message is parsed or stored.
4. How we use data
- Authenticate business owners, run the studio, and enforce app ownership.
- Connect the selected Instagram account or Facebook Page and maintain the subscription.
- Route an inbound DM to the correct app, create an app-scoped customer record, and issue a hashed, expiring, single-use link.
- Send the link reply back through the same channel (Instagram or Messenger).
- Run the customer workflow inside a server-validated session; identity is derived server-side and client payload overrides are blocked.
- Operate, debug, rate-limit, and secure the service; generate per-app analytics for the owning business.
- Run AI-assisted building: business prompts and app context may be sent to our language-model provider to generate or preview the app. We do not use customer DMs to train models.
We do not sell personal data, do not share it for cross-context behavioral advertising, and do not use Meta data for any purpose outside operating the connected feature.
6. Data retention
- Owner accounts and app data are kept while the workspace is active.
- One-time link tokens are short-lived, single-use, and expire automatically; only hashes are stored.
- Customer sessions and interactions persist inside the app store so the business can serve the customer, until the business or user requests deletion.
- OAuth access tokens are kept until the business disconnects the integration, the token is revoked in Meta settings, or deletion is requested.
- Server and webhook logs are kept short-term for security and debugging, then rotated.
7. Security
- Salted scrypt password hashes; passwords never returned to clients.
- Signed HttpOnly SameSite owner-session cookies; link-derived session cookies scoped per app, owner, and channel identity.
- Opaque customer tokens stored as hashes; raw secrets never leave the server.
- HMAC-SHA256 webhook signature validation on the raw request body before parsing.
- Per-app MongoDB isolation with tenant/identity indexes; sensitive collections write-protected at the runtime boundary.
- Rate limiting and TTL-backed storage hygiene.
No method is 100% secure, but we apply the controls above and limit employee-equivalent access to what is needed to operate the service.
8. Your rights
Depending on where you live (including the EU/UK under GDPR and California under CCPA/CPRA), you may have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. To exercise these rights, email sai@kiran.dev. End customers can also ask the business they messaged, which can view and remove that app's customer data from the workspace.
9. Data deletion instructions (Meta App Review)
Use this URL as both the Privacy Policy URL and the Data Deletion Instructions URL: https://bissai.netlify.app/privacy-policy#data-deletion
To delete your BissAI data:
- Email sai@kiran.dev from the address you signed up with (or include your Instagram username / Page name and the affected app name) with the subject "Data deletion request".
- Tell us the scope: (a) delete only the Instagram/Messenger connection and tokens, (b) delete one app and its customers/conversations, or (c) delete the whole workspace and all associated data.
- We confirm receipt, revoke/disconnect the Meta connection where applicable, delete tokens, customer records, sessions, interactions, and app data in scope, and reply when finished — within 30 days at most, usually much sooner.
You can also disconnect at any time without email: remove BissAI in Meta Account Center → Settings → Business integrations / Apps and websites, or remove the integration inside the BissAI workspace. Disconnecting stops future collection; email us if you also want historical data erased. Webhook log fragments may persist in short-term server logs until rotation.
10. Children's privacy
BissAI is a business tool and is not directed to children under 13 (or the higher minimum age in your jurisdiction). We do not knowingly collect children's data. If you believe a child's data was provided, contact us and we will delete it.
11. Changes to this policy
We will update this page when our practices change and revise the effective date above. Material changes will be highlighted in the app or by email where appropriate. Continued use after the effective date means you accept the updated policy.
12. Contact
Privacy questions or deletion requests: sai@kiran.dev. Please include "Privacy" in the subject line so your message is routed correctly.